Data processing agreement
Last update: 13 August 2026
This agreement applies when an organisation, for example a school, a cooperative, a clinic or a company, makes OurDaily available to people who belong to it. The data controller is NRC Company, the publisher of OurDaily. Full company details, including the VAT number and the registered office, are published on nrc.company. For anything about this document write to info@nrc.company.
The Italian version is the binding one. The English translation is provided for convenience.
Roles
The organisation is the controller of the data of the people it distributes the application to. NRC Company has no access to that data, because OurDaily does not send it: it stays on the devices. NRC Company acts as processor under article 28 of the GDPR only in the residual cases described below.
Cases where we process data on your behalf
- Support: when a person writes to us and attaches an exported file or a screenshot. We handle that material only to solve the request and delete it within thirty days from the closure of the case.
- Contracts and invoicing: contact details of the referents, processed by us as controller for civil and tax obligations.
Documented instructions
We process data only according to the written instructions of the controller, except where the law requires otherwise. If we believe an instruction infringes the GDPR we say so before carrying it out.
Confidentiality and security measures
Everyone working on the data is bound by confidentiality. Technical and organisational measures include encryption in transit, access limited to the people who need it, access logging, dependency updates and scheduled deletion of support material. The product model reduces the risk at the root, because data stays on the device of the user.
Sub processors
We use a hosting provider for the website and mail services for support. The current list is available on request at info@nrc.company. We announce any change at least thirty days in advance and the controller may object on reasonable grounds.
Artificial intelligence
We do not use controller data to train artificial intelligence models, neither ours nor those of third parties. OurDaily sends no content to artificial intelligence services: the task breakdown is a local rule engine. If in future we introduce a feature based on remote models, it will be optional, off by default, described before activation and covered by an update of this agreement.
OurDaily is not a high risk system under the European artificial intelligence regulation and it takes no automated decisions with legal effects on people.
Data breaches
If we become aware of a breach affecting data processed on behalf of the controller, we inform them without undue delay and in any case within forty eight hours, with the information needed for the notification required by articles 33 and 34 of the GDPR.
Assistance to the controller
On request we help the controller answer data subject requests, run impact assessments and deal with the supervisory authority. Since data stays on the device, answering an access or erasure request is usually done through the functions of the app.
Transfers
We transfer no data outside the European Economic Area. If a sub processor made it necessary, we would use the standard contractual clauses of the European Commission together with an assessment of the destination country.
Deletion and audit
At the end of the relationship we delete or return the material received, at the choice of the controller. We make available the information needed to demonstrate compliance with article 28 and accept agreed documentary audits, with reasonable notice and without prejudice to the security of other customers.